How to Build an OSINT Collection Plan for Cyber Threat Intelligence
Convert an intelligence requirement into lawful, safe, source-specific OSINT tasks with validation rules, stop conditions, and a clear owner.
An OSINT plan is a set of choices about what evidence to seek, where to seek it, how to validate it, and when to stop. It prevents the requirement from becoming an endless search of whatever is newly published.
Write the decision, deadline, scope, and current knowledge first. Then define which missing fact would most change the answer. Collection is successful when uncertainty falls enough for the consumer to decide—not when the archive becomes larger.
Break the Requirement Into Evidence Questions
Turn the main requirement into a small set of collectible questions. For each one, specify the subject, period, geography, language, and acceptable evidence. Rank it by decision value and urgency.
Separate facts that can be collected from judgments that require analysis. “Which affected product versions were publicly confirmed?” is collectible. “How likely is exploitation against us?” requires collection plus reasoning and internal exposure context.
Assign Sources by Expected Value
For each evidence question, list primary sources, independent corroboration, backup sources, access constraints, expected delay, and blind spots. Prefer the closest lawful source to the event. A copied article may be discoverable but should lead back to the original advisory, filing, code repository, or statement.
Include regional and language sources where the subject requires them. Record who will collect, how often, and what should trigger an unscheduled check.
Define Validation and Stop Conditions
Capture source, author or account, original time, retrieval time, exact claim, supporting artifact, and any edits. Check independence, context, authenticity, and whether a screenshot or translation can be traced to an original.
Stop when the answer meets the agreed confidence, the deadline arrives, the remaining gap cannot change the decision, or collection would exceed authorization. Feed results and gaps back into the requirement process described in the intelligence requirement guide.
Review the Plan as the Question Changes
Log useful and unproductive sources, response time, language gaps, and collection failures. Reallocate effort when one source consistently repeats others or when a new source closes a decisive gap.
A living plan is short enough to operate: requirement, evidence questions, source tasks, owners, cadence, handling rules, validation, and stopping conditions. Everything else can remain in supporting procedures.
Frequently asked questions
What should an OSINT collection plan start with?
Start with a prioritized intelligence requirement, the decision it supports, the deadline, and the evidence needed to answer it.
Does OSINT mean free information?
No. OSINT concerns availability and lawful access; sources may require subscriptions, specialist labor, translation, or tooling.
Should analysts collect everything in case it becomes useful?
No. Excess collection increases noise, cost, privacy exposure, and review burden. Define inclusion and stop rules.
Should public sources be archived?
Preserve decision-relevant evidence when lawful and permitted, including URL, time, capture method, and context, because content can change or disappear.
How should risky sources be handled?
Follow organizational legal, privacy, operational-security, and platform rules; use approved environments and stop when access or interaction exceeds authorization.